Hacking Tools, Hacker News & Cyber Security
ID: 454fd289-1928-5dbf-b348-f9c0c92974a6
STIX ID: report--454fd289-1928-5dbf-b348-f9c0c92974a6
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation credential-harvesting tool (and red-team utility) that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers. It uses a compiled executable plus a DLL injected into a headless Chromium process (Early Bird APC injection) to bypass Chrome's App-Bound Encryption via the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), and outputs structured JSON for operators; the report also provides usage examples, attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
